如何启动OpenSSL CMP模拟服务器?启动命令报错求助
启动OpenSSL CMP模拟服务器报错排查与解决
问题场景
尝试执行以下命令启动OpenSSL CMP模拟服务器:
openssl cmp -port 8080 -srv_trusted test-ca-cert.pem -srv_key test-server-key.pem -srv_cert test-server-cert.pem -rsp_cert test-client-cert2.pem -rsp_capubs test-ca-cert.pem &
执行后出现错误:
Error:- cmp_main:apps\cmp.c:2751:CMP info: using section(s) 'cmp' of OpenSSL configuration file 'C:\Program Files\Common Files\SSL/openssl.cnf' cmp_main:apps\cmp.c:2760:CMP info: no [cmp] section found in config file 'C:\Program Files\Common Files\SSL/openssl.cnf'; will thus use just [default] and unnamed section if present setup_srv_ctx:apps\cmp.c:1030:CMP warning: mock server will not be able to handle PBM-protected requests since -srv_secret is not given Could not open file or uri for loading certificate of the mock server from test-server-cert.pem 60410000:error:16000069:STORE routines:ossl_store_get0_loader_int:unregistered scheme:crypto\store\store_register.c:237:scheme=file 60410000:error:80000002:system library:file_open:No such file or directory:providers\implementations\storemgmt\file_store.c:267:calling stat(test-server-cert.pem) Unable to load certificate of the mock server
核心问题定位
错误日志中No such file or directory: calling stat(test-server-cert.pem)是启动失败的直接原因,说明OpenSSL无法找到指定的证书文件。其余提示为非致命性警告,不影响服务器启动,可后续按需处理。
解决步骤
确认文件存在与路径正确性
- 执行命令前,先检查当前工作目录下是否存在
test-server-cert.pem、test-server-key.pem等所有指定文件。Windows用dir命令,Linux/macOS用ls命令查看。 - 如果文件不在当前目录,使用绝对路径指定文件位置。例如Windows环境下:
注意路径包含空格时,需用双引号包裹避免参数解析错误。openssl cmp -port 8080 -srv_trusted "C:\certificates\test-ca-cert.pem" -srv_key "C:\certificates\test-server-key.pem" -srv_cert "C:\certificates\test-server-cert.pem" -rsp_cert "C:\certificates\test-client-cert2.pem" -rsp_capubs "C:\certificates\test-ca-cert.pem" &
- 执行命令前,先检查当前工作目录下是否存在
检查文件读取权限
- Windows系统:右键目标证书文件→属性→安全标签,确认当前执行命令的用户拥有读取权限。
- Linux/macOS系统:执行
chmod +r test-server-cert.pem(对应其他文件同理),赋予文件读取权限。
次要警告处理(可选)
- 针对
no [cmp] section found in config file:若无需自定义CMP规则,可直接忽略;若需要,在openssl.cnf中添加[cmp]section并配置相关参数。 - 针对
mock server will not be able to handle PBM-protected requests:若需支持PBM保护请求,在命令中添加-srv_secret <你的PBM密钥>参数即可。
- 针对
内容的提问来源于stack exchange,提问作者Neeraj Gahlawat
相关产品推荐
相关产品推荐

